|
|
|
@ -29,6 +29,9 @@ table inet forward {
|
|
|
|
|
|
|
|
|
|
ip6 saddr $prom_infra_v6 tcp dport 9100 counter accept
|
|
|
|
|
ip saddr $prom_infra_v4 udp dport 161 counter accept
|
|
|
|
|
|
|
|
|
|
ip6 saddr $bastion_ipv6 dport ssh accept
|
|
|
|
|
ip saddr $bastion_ipv4 dport ssh accept
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
chain forward_to_backbone {
|
|
|
|
@ -39,6 +42,9 @@ table inet forward {
|
|
|
|
|
|
|
|
|
|
ip6 saddr $prom_infra_v6 udp dport 161 counter accept
|
|
|
|
|
ip saddr $prom_infra_v4 udp dport 161 counter accept
|
|
|
|
|
|
|
|
|
|
ip6 saddr $bastion_ipv6 dport ssh accept
|
|
|
|
|
ip saddr $bastion_ipv4 dport ssh accept
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
chain forward_to_bmc {
|
|
|
|
@ -46,6 +52,9 @@ table inet forward {
|
|
|
|
|
|
|
|
|
|
ip6 saddr $prom_infra_v6 udp dport 161 counter accept
|
|
|
|
|
ip saddr $prom_infra_v4 udp dport 161 counter accept
|
|
|
|
|
|
|
|
|
|
ip6 saddr $bastion_ipv6 dport ssh accept
|
|
|
|
|
ip saddr $bastion_ipv4 dport ssh accept
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
chain forward_to_pve {
|
|
|
|
@ -53,6 +62,9 @@ table inet forward {
|
|
|
|
|
|
|
|
|
|
ip6 saddr $prom_infra_ipv6 tcp dport 9100 counter accept
|
|
|
|
|
ip saddr $prom_infra_ipv4 tcp dport 9100 counter accept
|
|
|
|
|
|
|
|
|
|
ip6 saddr $bastion_ipv6 dport ssh accept
|
|
|
|
|
ip saddr $bastion_ipv4 dport ssh accept
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
chain forward_to_router {
|
|
|
|
@ -60,6 +72,9 @@ table inet forward {
|
|
|
|
|
|
|
|
|
|
ip6 saddr $prom_infra_ipv6 tcp dport 9100 counter accept
|
|
|
|
|
ip saddr $prom_infra_ipv4 tcp dport 9100 counter accept
|
|
|
|
|
|
|
|
|
|
ip6 saddr $bastion_ipv6 dport ssh accept
|
|
|
|
|
ip saddr $bastion_ipv4 dport ssh accept
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
chain forward_to_internet {
|
|
|
|
|